TUCoPS :: Web :: Adminware, Control Panels :: b06-5717.htm

CPanel Multiple Cross Site Scription
CPanel Multiple Cross Site Scription
CPanel Multiple Cross Site Scription



#Aria-Security Team Advisory
# For English > 
# For Persian > 
#Original Advisory : http://aria-security.net/advisory/cpanel.txt 
#-----------------------------------------------------------
#Software: CPanel
#Tested On CPanel 10
#CPanel file Manager:
#PoC:
http://target.com:2082/frontend/[Servername]/files/seldir.html?dir=[XSS] 
#CPanel Password Protect DIRS :
#PoC: 
http://target.com:2082/frontend/[servername]/htaccess/newuser.html?user=[XSS]&pass=&dir=A VALID FOLDER 
*Press Go Back (hyperlink)
#In Password Protected DIR:
#PoC:
http://www.target:2082/frontend/[servername]/htaccess/newuser.html?user=[XSS]&pass=&dir=[XSS] 
#
#P.S : Attacker must be authenticated
#
#Contact: Advisory@aria-security.net 

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH